Data from Microsoft Defender for Endpoint is retained for 180 days, visible across the portal. However, in the advanced hunting investigation experience, it's accessible via a query for a period of 30 days. https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/data-storage-privacy?view=o365-worldwide#how-long-will-microsoft-store-my-data-what-is-microsofts-data-retention-policy
From Microsoft
https://learn.microsoft.com/en-us/defender-endpoint/data-storage-privacy?view=o365-worldwide#data-retention
Data Retention
Data from Microsoft Defender for Endpoint is retained for 180 days, visible across the portal.
Your data is kept and is available to you while the license is under grace period or suspended mode. At the end of this period, that data will be erased from Microsoft's systems to make it unrecoverable, no later than 180 days from contract termination or expiration.
In the advanced hunting investigation experience, it's accessible via a query for 30 days
https://learn.microsoft.com/en-us/defender-endpoint/data-storage-privacy?view=o365-worldwide#data-retention
Data from Microsoft Defender for Endpoint is retained for 180 days, visible across the portal.
Copilot: Alerts in the Microsoft 365 Defender portal are retained for 6 months (Option D). This retention period ensures that you have sufficient time to review and act on alerts.
C
The retention policy for alerts in the Microsoft 365 Defender portal depends on the type of alert and the service:
Defender for Cloud: Alerts are displayed for 90 days, even if the related resource is deleted.
Defender for Office 365 Plan 1: Alert metadata details are retained for 90 days, while entity metadata details for email are retained for 30 days. Activity alert details for audit logs are retained for 7 days.
Microsoft Defender for Endpoint: Data is retained for 180 days, but advanced hunting data is only available for 30 days.
C is correct until the exam is updated. After that it is D.
The English language version of this exam will be updated on April 26, 2024. Review the study guide linked in the “Tip” box for details on upcoming changes. If a localized version of this exam is available, it will be updated approximately eight weeks after this date.
Correct: D
https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/alerts-queue?view=o365-worldwide
On the top navigation you can:
Customize columns to add or remove columns
Apply filters
Display the alerts for a particular duration like 1 Day, 3 Days, 1 Week, 30 Days, and 6 Months
Export the alerts list to excel
Manage Alerts
"Alerts are displayed in the portal for 90 days, even if the resource related to the alert was deleted during that time. This is because the alert might indicate a potential breach to your organization that needs to be further investigated." - from: https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-overview
This section is not available anymore. Please use the main Exam Page.MS-102 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
northgaterebel
Highly Voted 1 year, 6 months ago[Removed]
Highly Voted 1 year, 5 months agoBeetleB
Most Recent 2 weeks, 4 days ago004b54b
1 month, 1 week agoDPAJA
1 month, 3 weeks agoAK_1234
4 months, 3 weeks agojedboy88
5 months agoJunetGoyal
5 months, 3 weeks agoKallely
6 months, 2 weeks agoKallely
6 months, 2 weeks agomark2525
7 months, 3 weeks agonorbe01
10 months agonicolasechavarria
11 months agoexamcrammer
1 year agoJamesWilliams
1 year, 1 month agoAmir1909
1 year, 3 months agoAncaMada112233
1 year, 6 months ago